mnemonic security podcast
Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across the cybersecurity landscape.
Each episode explores a specific topic within cybersecurity: from incident response, threat intelligence, AI, and geopolitics, to leadership, resilience, and the changing role of security leaders.
The podcast is tailored to cybersecurity practitioners and decision-makers who want grounded conversations about where cybersecurity is going, what organisations should prepare for, and what experienced people are seeing.
mnemonic security podcast
Magic Cat (Part 2)
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Magic Cat (part 2) with investigative journalist Martin Gundersen
This is the second part of our series about our investigation into Darcula, a phishing-as-a-service operation targeting victims globally, and the phishing kit platform Magic Cat. Over a period of 1,5 years, mnemonic researchers and an international investigative reporting team from the Norwegian media agency NRK, together with French Le Monde and German BR, looked into the technology, operations and individuals connected to this scam network.
The findings offer a rare look behind the scenes of this global phishing-as-a-service operation utilising Magic Cat. The research unveils hundreds of thousands of victims spanning the globe, unique technical insight into the software enabling hundreds of criminal subscribers, and a glimpse into the flashy lifestyle of the operators.
In this episode, Robby talks with Martin Gundersen from NRK about how they worked on this investigation, and what happened when they traveled to Thailand to confront the people behind the scam network.
If you haven’t listened to Part 1 of this series yet, check out episode 137 to hear Robby’s interview with mnemonic's security researchers Erlend Leiknes and Harrison Sand about the findings from their technical investigation into Magic Cat.
- mnemonic's technical blog about Magic Cat: https://www.mnemonic.io/resources/blog/exposing-darcula-a-rare-look-behind-the-scenes-of-a-global-phishing-as-a-service-operation/
- Inside the Scam Network at NRK: https://www.nrk.no/dokumentar/xl/inside-the-scam-network-1.17399135
- The Hunt for Darcula at NRK: https://www.nrk.no/dokumentar/xl/the-hunt-for-darcula-1.17399157
From our headquarters in Oslo, Norway, and on behalf of our host, Robby Peralta, welcome to the mnemonic security podcast.
Robby PeraltaSo I hope you didn't have to listen to part one to know that you shouldn't trust the links that are sent to us via SMS. But it was definitely interesting and surprising for me to hear what was behind those messages. Developed by a mysterious cat-loving dude named Darcula. But who actually sent the message? Where were they from? And how did they get my number? Not gonna lie, it would be pretty awesome to hear that story from the bad guys themselves. But it just so happens that we know a guy who was trying to make that happen. The podcast's favorite investigative journalist from Norway's public service broadcaster, NRK, and a man who has been in the rabbit hole together with my colleagues, this infamous magic cat. And yeah, I'll let him tell the rest.
Martin GundersenThank you for coming to NRK.
Robby PeraltaWoo! No, this is my job. Martin Gunderson, welcome to the podcast.
Martin GundersenThank you. I look very forward to being here.
Robby PeraltaI mean, uh, you come here every day.
Martin GundersenAt work.
Robby PeraltaTell us, uh, tell the everybody where we're at right now.
Martin GundersenSo we are at uh NRK, the Norwegian public broadcaster in a radio studio.
Robby PeraltaThis morning I was like telling my girlfriend, oh, we're going, I'm going to NRK, and she was like, Oh, you have to take a picture of the weatherman. And and I was actually in your reception this morning. Or that was not the reception, maybe.
Martin GundersenYes, it was the TV reception.
Robby PeraltaIt was a TV reception, yeah. And I was just like watching people go by and I was like, Oh, I want to take pictures, but I won't. I'm star struck Martin. It's nice to see you again.
Martin GundersenVery nice to be here.
Robby PeraltaYou were uh you've been here before though. Well, not in this specific room, but you've been on the podcast before.
Martin GundersenYes, last time we spoke about location data brokers and how we at NRK bought location data showing people's precise movement patterns, and how we found a person from uh my home city, Stavanger, and then we can track him to him going to a job interview, him going to the hospital, and just follow him around for a couple of months and how but crazy that was to see that his life in uh detail and how that ecosystem worked.
Robby PeraltaAnd that was what, two years ago now?
Martin GundersenYeah, I think it was 2020.
Robby PeraltaYeah. What's happened since then?
Martin GundersenUh since then, I think the industry has had a lot of problems. Some of them have shut down in Europe, but I also think I think a lot of those companies have tried to evolve, and some of the problems they've used are still there. So I think we still see a lot of data being shared in the real-time bidding ecosystem. So when you get a personalized ad, you share some information. And we've seen a lot of companies uh on the back end collecting that data for say OSINT for maybe good purposes and then maybe for worse purposes.
Robby PeraltaI just watched a presentation from uh Vivi Ringnes Berrefjord.
Martin GundersenYes, she's very into this.
Robby PeraltaOkay, you know, she is, yeah.
Martin GundersenAnd how that affects national security because I think it gets harder and harder to be, say, a spy or undercover cop when you have this enormous digital dragnet. And you need to be aware of that like when you start, because it's too late. Like you can't go back and fix it.
Robby PeraltaI want to name countries right now that have been like gathering that data and yeah, future spies that need to uh have parents that are just like extremely paranoid and don't let them be online or have phones because they'll never they'll they'll know who you are.
Martin GundersenYeah, yeah. It's uh tell your child.
Robby PeraltaYeah, tell your child that so again, nice to see you again. Uh part one of this, I don't know how long of a series it's gonna be because every time I talk to somebody, there's a there's another story behind the story. But uh part one of this will be my two colleagues that you know pretty well by this point in time, talking about their experience uncovering Magic Cat. Who came up with the word Magic Cat?
Martin GundersenI think it was the developer. Uh he uh or the the person behind it, Dark Law, seems to use Magikat in the software, but it also had been called Darcula suit some places or Darcula . So I think not everybody agrees on the naming, but I think from our end it's uh Magic Cat version one, version two, and version three.
Robby PeraltaRight.
Martin GundersenAnd then you can quibble about the details.
Robby PeraltaYeah. I guess that's what we're gonna I'm gonna ask you about uh all this story from from your perspective, right?
Martin GundersenYeah, so last year in February, I got um text message from Harrison Sand, and he said he was had something interesting to me to talk to. And we published May this year, so we have had some conversation going for a long time on uh Magic Cat and the people behind it. So his pitch was that we we think we have found some very interesting things on a very large fishing kit used to steal credit card information to defraud people, and it it's working globally, but it's quite popular here in Norway. So from there, what we had or what they had was that they had gotten access to a private Telegram group where people were talking both business and pleasure. So it was party photos, it was uh girls they'd hang out with, there was a lot of like OPSEC failures. Uh, but those OPSEC failures aren't that easy to exploit right away. So it took a lot of time to figure out what is important, uh, where to go because it was um what we've looked back. I think it's more than 40,000 messages we read in that private group and open groups where people share maybe not as open, but a lot of quite open stuff as well. And then uh there's like thousands of photos and videos. Uh everything is in Chinese. These are, I think, either Chinese nationals living in China or staying outside of China but having a Chinese heritage or an affiliation with Chinese culture. We have seen in these groups uh more non-Chinese people getting recruited or finding that ecosystem, and then people use Google Translate in both directions to communicate. But I think we've seen kind of that ecosystem from I think only two and three years ago like really growing and more and more maturing now.
Robby PeraltaYeah. So 40,000 messages, all in Chinese, across many different telegram groups, correct?
Martin GundersenYeah. So we I think Harrison and me kind of like just started with the phone translator on your app where you just use the the camera. And and that works kind of like quickly because like it's you need a system to properly translate things and to go back and have a structure. So that was kind of like where we started to just like the most important messages, just like poking around, checking, getting the vibe. And then after a while, I think it was Harrison first that kind of found a tool called TG Archive that allows you to export private groups and open groups to an offline copy. Oof. And that was amazing because then we later on we could run machine translation locally at NRK that translated everything to English, which was a lot easier to read. A lot of the translations are good but not perfect because they use a lot of slang, shorthand irony. Yeah, so so it's very internet speak but in Chinese. So I've the translations really have problems getting like the nuances, uh, but you kind of get the most important stuff. So we from that sometimes needed to talk with Chinese speakers to actually get proper translations, or if there was like key facts, getting them to read through the context around it to kind of figure out what they are actually saying. So that's a long way of saying that um it first it was more data than I think it was easy to go through as one person, and it was more people that you potentially could unmask or look into than was easy. So I think for Magic Cat, there was the main developer, Darcula . He was the guy providing software updates. Uh, if there was problems, he was the guy saying, Oh, there's a problem with the software right now. So it was kind of clear that he had that role. But then there was a lot of people around it, and we were unsure what their relationship with him or that uh telegram user was. Were they sellers of the software? Were they also people doing say more business-related stuff for the software? So we use a lot of time just mapping out how people spoke to each other, what they had of their own telegram communication channels. And I think um what I understand now is that this ecosystem is there's not high trust in this ecosystem, but it's kind of an ecosystem where people promote their services and are quite open in a way about what they can provide. So a lot of the people around Darcula were either sellers or people providing uh affiliate services. So Darkla was selling the software MagicCat where people gave away their credit card information and two-factor codes, so you could add a uh virtual card to your Google or Apple Pay, which would make it a lot easier to scam a person. But you need methods for scamming a person afterwards, so like which methods are best? Is it buying say expensive tickets and getting them refounded and then getting the refound on another credit card? Is it going to say luxury stores in specific countries and buying purses, or is it um having your own fake web shops where you make purchases that and there's no things sent, but you get the money right away. But at some point, like Visa or MasterCard will flag that site and take it down. So a lot of people had different kinds of things they were selling, and that's why they kind of went together and communicated as a community about like how to solve this problem about scamming a European person. Um so what we ended up was that we focused on Darcula, the person that we believed was kind of the creator and developer of the software. Um and uh mnemonic had come quite far with very strong initial findings on this person already. Um and we needed to bulletproof that and kind of like go from it seems that this is his name and this is his likely biographical data, to like we are very sure and we can publish it. And then we looked around for people around this network that kind of shared a lot of information that would make them easy to tell the story about how this works. And the person we ended up uh focusing on was a guy uh we called X66. He is kind of a scam influencer in a way, he had multiple channels where he scam influencer, yeah. Where he like, or you could say he did technical sales. Um so it's kind of like running a SaaS business. You need uh an evangelist that kind of promotes the software, and he was very good at promoting it. So he showed people customer success stories, um, and he also sometimes showed um more of his personal life in the especially the private telegram group, and when we also went really far back in his telegram history, we found earlier photos and videos that were more uh revealing about his um personal life. So he became more and more um like um obsec focused later on, but his kind of very early um career got him into trouble when we looked at it. So for us, like the core, I think, first piece of data on him was that he he usually filmed himself using the Magic Catch software where you could see victims roll in, like they you can see them live typing in information about themselves. And in a couple of videos, we could see him flashing a Thai phone number, and we were like, hmm, this is interesting. We've seen him saying things around him being in Thailand before, uh, and when we searched that phone number, we didn't find too much from the start. But when we did a second pass, we talked to a local Thai person that found that this number was used for a uh Thai messaging service, and from there we got a photo. Um that was helpful, but we didn't kind of fully solve it from there. But we from that uh from that point, no, like he could be Chris. That was the name on the that uh profile, and we had a picture, and then scrolling through things, we went back to him showing some photos on Instagram about people he've spoken to. So they these were kind of Thai girls which were more in the influencer scene, um, and in this one of the screenshots, it's kind of like you can see like this person also follows, and I was like, these people have a lot of followers, so like we couldn't manually go through all of them just to like look at profile pictures or names. Uh but I then went to which people they follow, which was a lot smaller amount, and then scrolled through a lot of those um Instagram influencer accounts, and then I found the same small picture again, the same profile picture we found on uh this uh Thai app, Chris. Chris. So then was like, hmm, interesting. And Chris didn't share that much, but he shared some things, and one of the things he shared was going to a nice um Japanese restaurant in Bangkok. On Instagram, I think he posted a video of several photos in a video, but on Telegram he just posted the same photos uh separately in the chat. So they were posted on the same day, everything was similar, and then we were like, Oh, I think we're onto something here. Are these photos of girls, by the way? No, this is about nice food. Okay, this is about um the entrance of the restaurant. Yeah, it's just bragging. It's not and I think it was kind of just like, oh, this was nice. So not nothing more. Day in my life, yeah. It's like a day in my life, not too important, but he shared it. And uh, when we went back, we also found the same cars, like very nice cars. It looked like the photo we're taking in China. Um, and they were posted on Telegram and then on Instagram, so that was kind of like the first leads we kind of could map the relation one-to-one, where you couldn't say 100% this is the same person uh from both accounts, but like you get farther and farther to this seems like the same person, and then we found more supporting facts around. So at some point we had seen so many bars, nice restaurants, and high-end stores in Bangkok that the Telegram account or the Instagram account had shared being to these places that we thought we should go. Um we're going to Thailand. Yeah, we're going to Thailand. And uh it was we have seen some photos from his apartment. We have tried to figure out which where that department was. And we kind of we knew a couple of places that likely would be. So we booked the tickets and I'm like, we'll figure out where the apartment is. This will this will get sold.
Robby PeraltaQuick question that's not very important. How do you convince like your your powers that be in NOK that hey, can I go to Thailand and go like find this guy? Like, Martin, you just wanted vacation.
Martin GundersenYeah, they were quite skeptical. Uh, but I think what was I think important in general is that um cybercrime stories and things happening on the internet is very abstract. You need to live in this world to kind of see it. So for most people, the what is happening in cyberspace is not very interesting. So actually going there is important for two reasons. One is to actually verify uh things you've seen online, like you've been a creep on the internet, but you're like you don't know 100% if you're correct, right? Because you've only seen, say, you've only seen one or two Google Maps images that seems to be correct, but you haven't actually been there. So you don't know if what you've not seen. So that's one thing. The other thing is that actually meeting the person and confronting them about what I've done, uh, checking if this is the right person was very important to me. Um, you kind of never fully know when everything is online, what what is real, what is uh not real. So we we went to Thailand and we had some things to go on. We had an apartment that we kind of knew the exterior of how the building would look. We never found that apartment, but what we also had was he was sharing on Telegram quite frequently about where he was, so we hoped he would share when we were there. And then he sometimes posted Instagram stories about where he was, and then he had a friend that we picked up in the research, and he shared even more on Instagram stories, and we thought he would be he looked to be criminally connected to Chris. So he was both a friend and he looked to be criminally connected. So we had two people sharing quite frequently about their life, and we thought if we were lucky and we land on a Friday, maybe they will post on the Saturday. So what happened was he didn't post on a Saturday uh about going out, he posted on a Sunday about his night on Saturday. So we um we kind of were not successful in that regard, but what we were successful on was that we found um this uh friend was called Ken. Uh he was he had been there um so
Robby Peraltaso Chris is x66. Would you name out in your thing? And Ken is this guy that is his friend, seemingly, that probably does business with him due to the pictures and the
Martin GundersenSo we we think it's very likely Chris is uh X66. There could be multiple people behind the account, but it he he is kind of like most likely one, and he's a very central person behind that account. And then Ken is he m might also be running that account, but we we don't have proof of that. But he had some patterns that kind of matched up him also participating in credit card fraud. So when we went there, we also had found a lot of their kind of social circle around them, and we've followed what people posted in real time, and we had a list of people we wanted to get in touch with. So when we were there, we ended up talking to a person at a bar that worked there that initially said they didn't know Ken that well, but afterwards he came up to us and said he'd been in contact with Ken. Ken doesn't know us and he wanted to talk to us. So we so he lied and then he hit up Ken. We don't know if he lied, but like it's hard knowing like the social relations.
Robby PeraltaNo, but first he said, I don't know what you're talking about.
Martin GundersenYeah, he like he knew he knew of him, but he gave the impression that he didn't know him that well.
Robby PeraltaYeah, and what did you guys do? You just go sit and have a beer over there and wait for him to change his mind? I don't know.
Martin GundersenNo, we yeah, no, we we drank non-alcoholic beers in a lot of nightclubs and bars. And we it initially we kind of went slow and didn't try to talk to that many people in the social circle and then try to like work from the outside in. But on the I think Sunday when we've been there for three days, we decided to kind of uh talk to a person we knew had been in contact with Ken, uh, and that kind of like he would know him, but we thought he wouldn't know him that well and maybe not would reach out to him right afterwards. So we kind of miscalculated in a way because we we I think hoped that we would get more information without actually being found out that we were looking for him. So we had a quite intense 24 hours where we tried to meet Ken. Ken wouldn't meet us. He only wanted to know what this was about. So it ended up being that we spoke on the phone with him, which we recorded where he denied being he said he was a businessman and he said that if we had proof we should go to the police. And afterwards, after the conversation, he sent us a photo of a person holding a gun with several guns in the background on the photo.
Robby PeraltaI saw that.
Martin GundersenSo we we gave him multiple opportunities to say or explain how his business operated and how our assumptions was wrong. And he to this point hasn't kind of fully uh used those opportunities.
Robby PeraltaSo you told him everything that you just laid it out what you were thinking.
Martin GundersenYes, we said we think he was involved with credit card fraud and he was friendly or criminally working with uh Chris and that they were kind of related to this X66 account. Uh so he he kind of have given uh a partial denial of that. Um and threatened you. Yes. So um after that we kind of didn't go too much out in Bangkok. I don't think that's very understandable. I don't think that threat was kind of really, really scary, but uh we you never know in a foreign country really like what's the relationships and local fixer we talked to uh said there was a a lot of problems with corruption, and we didn't know if we could go into hot water uh or if he would know people in a specific location that would call him. Uh so we we needed to kind of lay low afterwards. So um a long story short is that we we confronted uh Ken and then we confronted Chris as well. And when we laid everything out to Chris, he said that the photos we found of him was not of him, they were kind of from the internet or an online avatar, and he afterwards kind of deleted the telegram communicate channel we have had with him, the communications, and he also removed certain photos after we talked to Ken, and then he fully deleted his Instagram account afterwards. So we can't say for sure, and like he he said this is not him, but there are a lot of indications that we found the correct guy. So this is a long way of saying that like these people operate globally. We see them choosing different countries, uh like frequently just like pivoting to different countries where it's easier to scam people, because for some reason this country today is easier to exploit than this country tomorrow. And in only seven months, this Magikat tool was used to get at least 800,000 credit cards. I think that's kind of a lower bound estimate for that time period, and it kind of shows like the massive scale. He was one of the kind of more active people in the group sharing methods influencing the software, but I think there was other operators that was kind of bigger and victims, so it was there's a very big scale, and this ecosystem is maturing quite fast. So when we looked into them in February, they were quite kind of new on the scene. I think the last year there's been more and more stories about like Chinese fishing uh ecosystem. I think you had the DEF CON talk last August where another person had uh hacked into one of these fishing kits and told his story and about how he shared that with FBI. And I think we're only seeing like this ecosystem is maturing more and more with like new people coming in, the software becoming more sophisticated, and then the methods for exploit exploiting the credit cards, sending the messages. I think it's getting kind of more professionalized.
Robby PeraltaSo my colleague hits you up, and you guys go down this black hole or a rabbit hole together in a telegram group. And in this telegram group, you're introduced to this guy, x66, who is basically just kind of bragging about his life. You figure out who he is basically doing by OSINT, if I can call it that.
Martin GundersenYeah, yeah.
Robby PeraltaAnd what's funny to me, first of all, is that my colleagues kinda kind of found this Darcula guy, and he was not, he's the exact opposite of X66. He was quiet in the background, but he had made some uh some OPSSEC failures as well, just connected connected accounts. And uh you remember did Harrison tell you the story where he clicked on he got this guy to click on the link and it recorded his IP address, and that's kind of like the strongest link. Funny. Whereas this guy, he was just bragging and showing his girls and his uh uh he's the guy that had a ring for 300,000 kroners, right?
Martin GundersenWe we don't know if it's his hand. Yeah. But that was posted by that account.
Robby PeraltaYeah. So you guys are just going uh in this telegram group and translating Chinese. So Magic Magic Cat is um associated with this, and you go to Thailand and find Chris and Ken. And you leave there in in good shape.
Martin GundersenYeah, in good shape.
Robby PeraltaOkay. So I want to go into now the the adjacent services and more like the industry behind it. So uh if we go back to the telegram group, if I can call uh Chris or X66, he's kind of like a hype man. He's trying to maybe sort of promote Magic Cat uh and sort of keep this what do I call it, consortium of scammers because they're providing a platform. But uh can you tell me just more about the other adjacent services to because I was wondering like uh once once you st let's say I go in, I get that Posten uh message and I type in my credit card. I read in your article that they can sort of take money from me through a card terminal or add my card to an Apple Pay account. Like what are is that are those the only two ways that they were actually able to get money from me or
Martin GundersenYeah, I think it uh I think it depends on which card it is. Like most banks have quite sophisticated risk algorithm for credit card withdrawals, right? So if I was in Norway now and make a pay made a payment, and 10 seconds later I made a payment in Bangkok, that would likely get flagged in most banks as a suspicion moving pattern. So that there are a lot of risk assessments the banks do automatically that would stop some type of um like methods. So there are like innovations in getting around those risk systems and not getting flagged. Um so one of them is, for example, like a lot of people buy stuff on the internet and don't think too much about it. So if you create a fake e-commerce site and people make normal amounts of payments, that wouldn't usually get flagged right away because that's quite normal. Like people do that. Some people have a flag uh at their bank that says they don't allow the card to make any payments to e-commerce sites, but that's very few people. So that's a good way to do it. But you will get filed out eventually because when a couple of customers report the fraud, it would take a bit of time, but the bank would tell the bigger payment system, uh Visa MasterCard, about it, and then at some point it will get taken down. Uh, another way is buying these points of sale systems that you have in the source, and they use them for their own sake. I think what they do is they create fake uh stores and they pay those stores in a way, and that also works for a limited amount of time until it gets found out, and then you need to cycle the either um terminals or create a new company that kind of gets the amount of the money. I also think we've seen a lot of like more refound schemes where you make a proper payment to something and then they redraw the amount.
Robby PeraltaThey reverse the transaction, right?
Martin GundersenThey refound the transaction, but I think they get it to another card. So through that, they kind of launder the money through a legitimate business where you would kind of make not super high-end transactions, but quite large transactions. And then the kind of simple, simplest method, in a way, is that you have a person go into electronic stores or high-end luxury stores and buying items because they're very easy to resell. So you you wouldn't lose too much value reselling a Nintendo Switch or reselling uh a Louis Vuitton handbag.
Robby PeraltaYeah, right. So it just makes me think that uh I want to use the word organized crime because it has to be, right? Because if you have to you have to have some sort of like backing for creating like fake stores or or what do you think about that?
Martin GundersenI think it's a combination where I think a lot of the people we've looked into would fit interpreted entrepreneur label quite well. And I think when the ecosystem matures, I think it will get more and more it will look more and more like organized crime. So I think kind of the move is that it will be more organized and you would have, I think, more established actors moving into this scene. I think Magikat is one fishing kit, there are other fishing kits, and there might be differences where, say, a specific organized crime syndicate prefer another fishing kit, right? So we we didn't see specific syndicates or organized crime uh operations being named in a way, but I wouldn't be surprised if behind some of the bigger telegram accounts or operators there are proper organizations that are a lot of people working on it and they have business routines and structures and ways to limit their exposure. And also, I think when we reached uh Yu Sheng-C, the person we believe is behind the Darcula, um, we got a response from another people claiming to not be him, but claiming to work in his company. And he said that uh Yu Sheng-C had left the company after our inquiries. Yes, and uh like it's hard knowing how much to trust this information, but uh from what he is telling is that you have developers creating software, and then you have some kind of more money people, more business people that kind of packs it and fixes it and kind of have an idea on how to kind of package this, and then you have a system for selling the software. So one model is that a person creates the software and a lot of people are allowed to resell it, uh, or you can have a system where you can rent out the software. We you're not allowed to install it locally, but you can kind of rent the web server running it. And I think we've seen every kind of nuance of that. Either you can kind of get a physical copy, but you need a license key, which uh were sometimes for Magic Cat, but other resellers would just sell you the web server, and then you just log in, you wouldn't need to think about anything, you can even buy the domain. So the only thing you need to uh think about was paying in crypto and then how to send out the messages. Uh so in this system, you kind of have the Magic Cat phishing kits, you have the method for sending out the text messages. What we've been told is that for the Chinese ecosystem, it's more common to send iMessage or RCS because if uh you send traditional SMSs, it would be strange if you send a lot of them from Southeast Asia. So the banks have or the telecommunication industry, you need to pay different actors for sending SMSs, especially if there's high volume. And if suddenly Thailand is popping up as a country sending a lot of SMSs to other countries, it would sooner get flagged. But if you kind of have your operation in Sweden and send a lot of messages to Norway, that wouldn't be flagged as fast because that would be very natural. So if you're kind of based in the Southeast Asia, it's just easier to use the modern text messages because they are end-to-end encrypted and they don't go through the telecommunication industry route, they go through the interwebs. So uh then you're kind of fighting Google and Apple to get around their security mechanisms, but you don't have problems where Telenor doesn't get involved in that case. Yes, for sure. Or they they would get involved afterwards. So if I get a suspicious text message from a person I don't know, there's a small button you can press report. And in some countries, if I do that, it will be sent to Google or Apple, but it could also be sent to the telecommunication provider, and that could help them tuning the messages or their systems as well.
Robby PeraltaThey still have a chance to do something about it.
Martin GundersenYeah, yeah. But it's they have to be aware of it. Yeah, and it's harder, I think, for countries to deal with it because it's uh a very big corporation outside of your country running it, and it's kind of run, I think, quite like similar for each country. Like it's harder to make specializations or local fixes because it's kind of like a global global problem. Yeah, global problem and global solution or product you're using.
Robby PeraltaRight. So uh did you ever like get in contact with like a lawyer that was representing them? I know that's a common way for people to hide themselves in organized crime, is uh have like a a very uh questionable lawyer that's kind of uh
Martin GundersenSo this person that reached out claiming to work for the same company as Yusheng Si, he did not want to disclose more about his real identity or which company he worked for.
Robby PeraltaYeah.
Martin GundersenSo we don't know. Yeah. Um and we have never gotten a email or um letter from a lawyer about this matter. It might happen, but we haven't seen it this far.
Robby PeraltaAnd speaking of the word uh law, technically speaking, like uh you can share all this evidence that you've collected. Shouldn't this guy have been arrested?
Martin GundersenI think like now our findings are public. I think law enforcement could look at it and think on a lot of like like the fraud side, like of different problems we have, what should I prioritize? Um it's up to them to decide. I think the Chinese uh ecosystem we've looked into only would get bigger, and the l the risk doesn't look to be that big at this moment. So I think maybe like a pr the parallel would be the China the Russia, uh Russian-speaking ransomware ecosystem where you had a lot of years where there was a like it was no obvious risk to you, and then suddenly some people got in jail or they were unmasked, so they would need to live less um obviously, yeah. Uh and then maybe they would just need to stay in non-extradition countries, right? The rest of their lives. So, like there's a lot of ways the like different actors could increase the risk or make it less appealing to go into this uh ecosystem. And I think if we go 10 years in the future, I think a lot of the people or groups will get more and more exposed. There will be likely some law enforcement action. But I think a problem with uh this type of fraud is that it looks very small when you look at per victim, because it's a couple of hundred dollars or a couple of thousand dollars usually. So you need a lot of victims to say this is a lot of money getting stolen. And so that's a problem from the police side because a lot of the investigation are bottom-up. Uh, and there are a lot of very important police work, so like terrorism, uh, you have organized crime where there's more violence or narcotics that I think have been more prioritized for uh kind of like where you go specifically against an actor to expose them or prosecute them. And I don't think we've seen too much on the fishing scene, the Chinese fishing scene until now. The closest thing is fishing kit called Laphost. That was um there was law enforcement action against last year, but I I don't think we've seen too much uh overt action on the other fishing kits that are Chinese. Yeah.
Robby PeraltaSo, Martin, what what has happened ever since when you dropped this on the 4th of May, correct?
Martin GundersenYeah, it was published 4th of May. After we published, we followed up with a story about Darcula going dark. He uh he read our first message where we wrote him about his first name, that you shane, we would like to talk to you. And he read that message, but he didn't read the other messages uh on Telegram. So we sent him messages on his personal emails and called his personal phone. Uh we never got a response from him directly, but he never appeared to log into Telegram again. And that was an account that's been quite active uh on Telegram. And at some point, Telegram took down the account and has been not reinserted, so reinstated. So he appeared to have kind of closed down his criminal alias, as well as we've seen some personal accounts also being scrubbed from the internet. We've also seen a Gmail account being deactivated. So we don't fully know, but it looks like this person has gone under underground, ghosts, ghosted, and what we also saw was that people have been asking about buying Magikat and being told that it's not longer possible to buy licenses. And then we when we tried to approach sellers of Magikat, they either sent us to uh other fishing kits or said it's been discontinued. So um it looks like it's down. We talked to Netcraft, which kind of looks into uh domains, takedowns, so they specialize in taking down domains. They said they've seen a 65% drop um following the reporting. Um we don't know how much they will get back, if there will be uh other people kind of taking out the mantle. We've seen what appears to be cracked version of the software being sold. So that could be kind of it will go back, but I also think that the win has been taken out of the software development kit where if they don't develop new features or it doesn't get kind of like bug fixes, at some point I think a lot of stuff will break. So it will get less and less usable if you don't have an experienced developer handling the software and taking it into the future.
Robby PeraltaAnd I want to say I read another article saying that somebody else tried to like call Darcula out and like take his software down, but they had just switched all their infrastructure like that. So this your effect with this research has done a a huge, like a much larger effect, because that was what, three weeks ago now? It's had a much more larger effect than other previous sort of attempts to try to take down Magic Cat.
Martin GundersenI I hope so. But I think the big thing is that when you unmask the players behind it, you really increases the stakes. Yeah. Uh and the parallel here is that Mr. Deepfakes, one of the largest like non-consensual porn sites in the world, the the administrator of that site appears to have been unmasked. And when that happened, the site went down. So I I think like it's hard for a lot of people to do this in the open. I think people would wouldn't prefer doing it uh if their names were attached to it. And I think we're approaching that with the Chinese fishing scene. That I think more and more players will get exposed by us or by somebody else, and that would kind of increase the stakes and make it less interesting to try to do it.
Robby PeraltaDoxing is actually the most powerful form of uh making people stop in this cyberspace.
Martin GundersenYeah, I wouldn't say doxing, I would say unmasking. Unmasking, yeah. But yeah, I I've and I think there's a big difference between doxing and unmasking. But yeah, I think and I that's kind of like what we as journalists and I also think like say IT security companies can do is kind of get the facts out. And then it's a question about law enforcement or other actors if they should intervene. And then you have banks, uh telecommunications partners, uh the big tech, they could also do certain things that would make it even harder to do this type of crime.
Robby PeraltaWell, Martin, thank you so much for uh taking the extra mile. Even risking your personal safety going to uh Well, you got to go to Thailand. That's kind of nice.
Martin GundersenI was very nice. It was perfect weather. Thank you for being here.
Robby PeraltaThank you so much for having me. Well, that's all for today, folks. Thank you for tuning in to the mnemonic security podcast. If you have any concepts or ideas that you'd like us to discuss on future episodes, please feel free to hit me up on LinkedIn or to send us a mail at podcast at mnemonic.no. Thank you for listening. We'll see you next time.